Technique ID,Detection Available,Link,score T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13 T1568.001,No,-,0 T1218.010,No,-,0 T1213,No,-,0 T1519,No,-,0 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike.yml,2 T1021.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/smb_traffic_spike___mltk.yml,2 T1027.002,No,-,0 T1020,No,-,0 T1158,No,-,0 T1164,No,-,0 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_symlink_to_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy_with_wmic_and_powershell.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/credential_dumping_via_copy_command_from_shadow_copy.yml,4 T1003.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/creation_of_shadow_copy.yml,4 T1201,No,-,0 T1578.003,No,-,0 T1049,No,-,0 T1547.011,No,-,0 T1185,No,-,0 T1564.005,No,-,0 T1119,No,-,0 T1037,No,-,0 T1055.005,No,-,0 T1199,No,-,0 T1547.003,No,-,0 T1069.003,No,-,0 T1537,No,-,0 T1192,No,-,0 T1146,No,-,0 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/short_lived_windows_accounts.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_local_admin_accounts_using_net_exe.yml,3 T1136.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_local_admin_account.yml,3 T1069,No,-,0 T1044,No,-,0 T1505,No,-,0 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/hosts_receiving_high_volume_of_network_traffic_from_email_server.yml,2 T1114.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_servers_sending_high_volume_traffic_to_hosts.yml,2 T1542.001,No,-,0 T1514,No,-,0 T1552,No,-,0 T1052,No,-,0 T1556.003,No,-,0 T1563.001,No,-,0 T1499.002,No,-,0 T1574,No,-,1 T1563,No,-,0 T1055.014,No,-,0 T1134.005,No,-,0 T1558,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,2 T1542.002,No,-,0 T1077,No,-,0 T1121,No,-,0 T1059.006,No,-,0 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/clients_connecting_to_multiple_dns_servers.yml,2 T1048.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/protocol_or_port_mismatch.yml,2 T1574.002,No,-,0 T1079,No,-,0 T1213.001,No,-,0 T1504,No,-,0 T1090.001,No,-,0 T1083,No,-,0 T1552.001,No,-,0 T1134,No,-,0 T1144,No,-,0 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_user_account_lockouts.yml,2 T1078.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_excessive_account_lockouts_from_endpoint.yml,2 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_s3_bucket_deletion.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_open_s3_buckets.yml,3 T1530,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_s3_access_from_a_new_ip.yml,3 T1120,No,-,0 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/disabling_remote_user_account_control.yml,2 T1112,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_reg_exe_process.yml,2 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_file_creation.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/shim_database_installation_with_suspicious_parameters.yml,3 T1546.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_for_creating_shim_databases.yml,3 T1550,No,-,1 T1547.004,No,-,0 T1218.003,No,-,0 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/child_processes_of_spoolsv_exe.yml,2 T1068,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_child_process_of_zoom.yml,2 T1059.004,No,-,0 T1011.001,No,-,0 T1100,No,-,0 T1054,No,-,0 T1021,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,7 T1564,No,-,0 T1547.009,No,-,0 T1022,No,-,0 T1102.001,No,-,0 T1105,No,-,0 T1559.001,No,-,0 T1036.001,No,-,0 T1070.004,No,-,0 T1578.004,No,-,0 T1572,No,-,0 T1546.009,No,-,0 T1518,No,-,0 T1501,No,-,0 T1053.002,No,-,0 T1548.002,No,-,0 T1212,No,-,0 T1065,No,-,0 T1546.003,No,-,0 T1175,No,-,0 T1552.004,No,-,0 T1223,No,-,0 T1574.008,No,-,0 T1015,No,-,0 T1567.002,No,-,0 T1218.002,No,-,0 T1023,No,-,0 T1183,No,-,0 T1125,No,-,0 T1200,No,-,0 T1108,No,-,0 T1578.001,No,-,0 T1136,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___account_harvesting.yml,4 T1573.002,No,-,0 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_prohibited_applications_spawning_cmd_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_use_of_cmd_exe_to_launch_script_interpreters.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mshta_exe_running_scripts_in_command_line_arguments.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_or_delete_windows_shares_using_net_exe.yml,7 T1059.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,7 T1147,No,-,0 T1004,No,-,0 T1205,No,-,0 T1552.006,No,-,0 T1104,No,-,0 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unload_sysmon_filter_driver.yml,2 T1562.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_stop_security_service.yml,2 T1056,No,-,0 T1219,No,-,0 T1567.001,No,-,0 T1566.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_lnk_file_launching_a_process.yml,1 T1036.002,No,-,0 T1046,No,-,0 T1115,No,-,0 T1554,No,-,0 T1546.002,No,-,0 T1565.001,No,-,0 T1502,No,-,0 T1211,No,-,0 T1072,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_tools_built_by_nirsoft.yml,1 T1080,No,-,0 T1560.003,No,-,0 T1180,No,-,0 T1070.005,No,-,0 T1542.003,No,-,0 T1555.001,No,-,0 T1052.001,No,-,0 T1056.004,No,-,0 T1094,No,-,0 T1001.003,No,-,0 T1076,No,-,0 T1215,No,-,0 T1218.007,No,-,0 T1178,No,-,0 T1171,No,-,0 T1140,No,-,0 T1025,No,-,0 T1136.003,No,-,0 T1547.007,No,-,0 T1552.003,No,-,0 T1213.002,No,-,0 T1001.001,No,-,0 T1195.002,No,-,0 T1053,No,-,4 T1209,No,-,0 T1069.001,No,-,0 T1193,No,-,0 T1179,No,-,0 T1098.003,No,-,0 T1505.002,No,-,0 T1059.002,No,-,0 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/multiple_okta_users_with_invalid_credentails_from_the_same_ip.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_failed_sso_attempts.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_account_lockout_events.yml,4 T1078.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/okta_user_logins_from_multiple_cities.yml,4 T1562.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_launching_netsh.yml,1 T1563.002,No,-,0 T1558.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/kerberoasting_spn_request_with_rc4_encryption.yml,1 T1099,No,-,0 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_command_line_argument.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___multiple_suspicious_command_line_arguments.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___connect_to_internet_with_hidden_window.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_set_default_powershell_execution_policy_to_unrestricted_or_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/processes_created_by_netsh.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process_with_obfuscation_techniques.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___execution_policy_bypass.yml,8 T1059.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_psexec_with_accepteula_flag.yml,8 T1195.001,No,-,0 T1497.001,No,-,0 T1536,No,-,0 T1058,No,-,0 T1005,No,-,0 T1148,No,-,0 T1038,No,-,0 T1552.002,No,-,0 T1218.005,No,-,0 T1486,No,-,0 T1003.008,No,-,0 T1078,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_fraud___anomalous_user_clickspeed.yml,21 T1053.001,No,-,0 T1557.001,No,-,0 T1500,No,-,0 T1170,No,-,0 T1166,No,-,0 T1051,No,-,0 T1498.001,No,-,0 T1210,No,-,0 T1074.002,No,-,0 T1202,No,-,0 T1495,No,-,0 T1561.002,No,-,0 T1102.003,No,-,0 T1574.009,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_path_interception_by_creation_of_program_exe.yml,1 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_f5_tmui_rct_cve_2020_5902.yml,2 T1190,Yes,https://github.com/splunk/security-content/blob/develop/detections/sql_injection_with_long_urls.yml,2 T1095,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_large_outbound_icmp_packets.yml,1 T1087.001,No,-,0 T1218.008,No,-,0 T1547.005,No,-,0 T1040,No,-,0 T1153,No,-,0 T1087.003,No,-,0 T1071,No,-,10 T1129,No,-,0 T1204.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/uncommon_processes_on_endpoint.yml,1 T1155,No,-,0 T1085,No,-,0 T1177,No,-,0 T1021.004,No,-,0 T1042,No,-,0 T1090.003,No,-,0 T1134.004,No,-,0 T1053.004,No,-,0 T1221,No,-,0 T1557,No,-,0 T1003.007,No,-,0 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/windows_event_log_cleared.yml,2 T1070.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_wevtutil_usage.yml,2 T1555.003,No,-,0 T1132.002,No,-,0 T1113,No,-,0 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_attackers_scanning_for_vulnerable_jboss_servers.yml,2 T1082,Yes,https://github.com/splunk/security-content/blob/develop/detections/web_servers_executing_suspicious_processes.yml,2 T1546.008,Yes,https://github.com/splunk/security-content/blob/develop/detections/overwriting_accessibility_binaries.yml,1 T1208,No,-,0 T1499,No,-,0 T1561,No,-,0 T1497.003,No,-,0 T1009,No,-,0 T1496,No,-,0 T1216.001,No,-,0 T1011,No,-,0 T1548.004,No,-,0 T1127,No,-,0 T1562.006,No,-,0 T1124,No,-,0 T1126,No,-,0 T1055.004,No,-,0 T1098.002,No,-,0 T1505.003,No,-,0 T1031,No,-,0 T1574.007,No,-,0 T1137.002,No,-,0 T1491.002,No,-,0 T1548.003,No,-,0 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_outliers___mltk.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_requests_resolved_by_unauthorized_dns_servers.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_query_length_with_high_standard_deviation.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detection_of_dns_tunnels.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_long_dns_txt_record_response.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/dns_record_changed.yml,7 T1071.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/excessive_dns_failures.yml,7 T1021.003,No,-,0 T1048.002,No,-,0 T1196,No,-,0 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/tor_traffic.yml,2 T1071.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_web_traffic_to_dynamic_domain_providers.yml,2 T1169,No,-,0 T1128,No,-,0 T1548.001,No,-,0 T1172,No,-,0 T1149,No,-,0 T1543,No,-,1 T1498.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/large_volume_of_dns_any_queries.yml,1 T1182,No,-,0 T1547,No,-,3 T1059,No,-,15 T1093,No,-,0 T1553.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempt_to_add_certificate_to_untrusted_store.yml,1 T1037.002,No,-,0 T1098,No,-,0 T1527,No,-,0 T1220,No,-,0 T1034,No,-,0 T1141,No,-,0 T1116,No,-,0 T1003.005,No,-,0 T1041,No,-,0 T1055.002,No,-,0 T1522,No,-,0 T1074.001,No,-,0 T1071.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_outbound_smb_traffic.yml,1 T1111,No,-,0 T1546.005,No,-,0 T1050,No,-,0 T1574.001,No,-,0 T1055.011,No,-,0 T1184,No,-,0 T1074,No,-,0 T1542,No,-,0 T1073,No,-,0 T1092,No,-,0 T1014,No,-,0 T1189,No,-,0 T1137.006,No,-,0 T1075,No,-,0 T1087.002,No,-,0 T1134.003,No,-,0 T1222.002,No,-,0 T1562.002,No,-,0 T1548,No,-,0 T1035,No,-,0 T1555,No,-,0 T1561.001,No,-,0 T1098.004,No,-,0 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_traffic.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_process_instantiation_via_wmi.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_process_running_on_system.yml,4 T1021.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_desktop_network_bruteforce.yml,4 T1017,No,-,0 T1205.001,No,-,0 T1569.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/first_time_seen_running_windows_service.yml,1 T1565.002,No,-,0 T1569,No,-,1 T1499.004,No,-,0 T1037.005,No,-,0 T1553.003,No,-,0 T1546.004,No,-,0 T1053.003,No,-,0 T1560,No,-,0 T1181,No,-,0 T1565,No,-,0 T1131,No,-,0 T1558.002,No,-,0 T1218.009,No,-,0 T1001.002,No,-,0 T1078.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/identify_new_user_accounts.yml,1 T1160,No,-,0 T1060,No,-,0 T1560.001,No,-,0 T1489,No,-,0 T1207,No,-,0 T1204,No,-,1 T1553.001,No,-,0 T1018,No,-,0 T1547.002,No,-,0 T1091,No,-,0 T1019,No,-,0 T1543.001,No,-,0 T1555.002,No,-,0 T1492,No,-,0 T1048,Yes,https://github.com/splunk/security-content/blob/develop/detections/prohibited_network_traffic_allowed.yml,3 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_gcr_container_uploaded.yml,2 T1525,Yes,https://github.com/splunk/security-content/blob/develop/detections/new_container_uploaded_to_aws_ecr.yml,2 T1574.004,No,-,0 T1550.003,No,-,0 T1480,No,-,0 T1161,No,-,0 T1558.001,No,-,0 T1214,No,-,0 T1546.006,No,-,0 T1556,No,-,0 T1087,No,-,0 T1574.005,No,-,0 T1506,No,-,0 T1564.001,No,-,0 T1130,No,-,0 T1139,No,-,0 T1045,No,-,0 T1546.007,No,-,0 T1032,No,-,0 T1090,No,-,0 T1498,No,-,1 T1027.005,No,-,0 T1543.004,No,-,0 T1027,Yes,https://github.com/splunk/security-content/blob/develop/detections/malicious_powershell_process___encoded_command.yml,1 T1566.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_dns_requests_to_phishing_sites_leveraging_evilginx2.yml,1 T1097,No,-,0 T1546,No,-,5 T1556.002,No,-,0 T1176,No,-,0 T1562,No,-,3 T1187,No,-,0 T1070.006,No,-,0 T1186,No,-,0 T1057,No,-,0 T1543.002,No,-,0 T1574.010,No,-,0 T1028,No,-,0 T1010,No,-,0 T1565.003,No,-,0 T1056.001,No,-,0 T1110.003,No,-,0 T1109,No,-,0 T1142,No,-,0 T1154,No,-,0 T1547.006,No,-,0 T1487,No,-,0 T1037.003,No,-,0 T1071.003,No,-,0 T1027.003,No,-,0 T1055.012,No,-,0 T1056.003,No,-,0 T1090.004,No,-,0 T1137,No,-,0 T1485,Yes,https://github.com/splunk/security-content/blob/develop/detections/deleting_shadow_copies.yml,1 T1110.001,No,-,0 T1204.001,No,-,0 T1222.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/hiding_files_and_directories_with_attrib_exe.yml,1 T1137.001,No,-,0 T1027.004,No,-,0 T1106,No,-,0 T1036.005,No,-,0 T1553.002,No,-,0 T1070.003,No,-,0 T1218.001,No,-,0 T1482,No,-,0 T1137.005,No,-,0 T1013,No,-,0 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_zeek.yml,2 T1203,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_windows_dns_sigred_via_splunk_stream.yml,2 T1123,No,-,0 T1021.005,No,-,0 T1574.006,No,-,0 T1012,No,-,0 T1499.003,No,-,0 T1218.004,No,-,0 T1168,No,-,0 T1048.001,No,-,0 T1222,No,-,1 T1173,No,-,0 T1156,No,-,0 T1543.003,Yes,https://github.com/splunk/security-content/blob/develop/detections/sc_exe_manipulating_windows_services.yml,1 T1134.002,No,-,0 T1055.003,No,-,0 T1480.001,No,-,0 T1570,No,-,0 T1101,No,-,0 T1029,No,-,0 T1534,No,-,0 T1556.001,No,-,0 T1086,No,-,0 T1494,No,-,0 T1491.001,No,-,0 T1056.002,No,-,0 T1008,No,-,0 T1036.004,No,-,0 T1195.003,No,-,0 T1055,No,-,0 T1568.003,No,-,0 T1007,No,-,0 T1574.011,No,-,0 T1067,No,-,0 T1505.001,No,-,0 T1206,No,-,0 T1062,No,-,0 T1152,No,-,0 T1564.003,No,-,0 T1114.003,No,-,0 T1528,No,-,0 T1037.001,No,-,0 T1198,No,-,0 T1064,No,-,0 T1145,No,-,0 T1059.005,No,-,0 T1493,No,-,0 T1110.004,No,-,0 T1055.008,No,-,0 T1568,No,-,0 T1081,No,-,0 T1055.001,No,-,0 T1194,No,-,0 T1218.011,Yes,https://github.com/splunk/security-content/blob/develop/detections/rundll_loading_dll_by_ordinal.yml,1 T1546.010,No,-,0 T1002,No,-,0 T1039,No,-,0 T1573.001,No,-,0 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_used_for_forcing_a_reboot.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/schtasks_scheduling_job_on_remote_system.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_tasks_used_in_badrabbit_ransomware.yml,4 T1053.005,Yes,https://github.com/splunk/security-content/blob/develop/detections/scheduled_task_name_used_by_dragonfly_threat_actors.yml,4 T1546.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_changes_to_file_associations.yml,1 T1550.001,No,-,0 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_using_loaded_images.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/dump_lsass_via_comsvcs_dll.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/create_remote_thread_into_lsass.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/access_lsass_memory_for_dump_creation.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_credential_dumping_through_lsass_access.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_mimikatz_via_powershell_and_eventcode_4703.yml,7 T1003.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/unsigned_image_loaded_by_lsass.yml,7 T1538,No,-,0 T1191,No,-,0 T1001,No,-,0 T1150,No,-,0 T1098.001,No,-,0 T1568.002,No,-,0 T1547.008,No,-,0 T1133,No,-,0 T1559.002,No,-,0 T1567,No,-,0 T1084,No,-,0 T1114,No,-,3 T1070.002,No,-,0 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_in_previously_unseen_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_city.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cloud_provisioning_from_previously_unseen_country.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_started_in_previously_unused_region.yml,8 T1535,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_console_login_by_user_from_new_region.yml,8 T1564.002,No,-,0 T1484,No,-,0 T1055.009,No,-,0 T1135,No,-,0 T1574.012,No,-,0 T1564.004,No,-,0 T1163,No,-,0 T1562.007,No,-,0 T1003.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/attempted_credential_dump_from_registry_via_reg_exe.yml,1 T1090.002,No,-,0 T1564.006,No,-,0 T1066,No,-,0 T1055.013,No,-,0 T1491,No,-,0 T1546.012,No,-,0 T1197,No,-,0 T1547.010,No,-,0 T1016,No,-,0 T1499.001,No,-,0 T1573,No,-,0 T1127.001,No,-,0 T1117,No,-,0 T1027.001,No,-,0 T1546.014,No,-,0 T1162,No,-,0 T1559,No,-,0 T1503,No,-,0 T1195,No,-,0 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/script_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/process_execution_via_wmi.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/remote_wmi_command_attempt.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_temporary_event_subscription.yml,6 T1047,Yes,https://github.com/splunk/security-content/blob/develop/detections/wmi_permanent_event_subscription___sysmon.yml,6 T1122,No,-,0 T1560.002,No,-,0 T1110.002,No,-,0 T1566,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email___uba_anomaly.yml,5 T1059.007,No,-,0 T1043,No,-,0 T1488,No,-,0 T1529,No,-,0 T1096,No,-,0 T1550.004,No,-,0 T1217,No,-,0 T1218,No,-,1 T1578,No,-,0 T1546.015,No,-,0 T1006,No,-,0 T1137.003,No,-,0 T1174,No,-,0 T1134.001,No,-,0 T1070,Yes,https://github.com/splunk/security-content/blob/develop/detections/usn_journal_deletion.yml,3 T1550.002,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_activity_related_to_pass_the_hash_attacks.yml,1 T1030,No,-,0 T1137.004,No,-,0 T1036.006,No,-,0 T1539,No,-,0 T1518.001,No,-,0 T1061,No,-,0 T1151,No,-,0 T1578.002,No,-,0 T1037.004,No,-,0 T1107,No,-,0 T1114.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/email_files_written_outside_of_the_outlook_directory.yml,1 T1103,No,-,0 T1490,No,-,0 T1483,No,-,0 T1088,No,-,0 T1159,No,-,0 T1165,No,-,0 T1132.001,No,-,0 T1003.004,No,-,0 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_oulook_exe_writing_a__zip_file.yml,2 T1566.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_email_attachment_extensions.yml,2 T1102,No,-,0 T1024,No,-,0 T1157,No,-,0 T1003,No,-,12 T1087.004,No,-,0 T1552.005,No,-,0 T1562.003,No,-,0 T1553,No,-,1 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/reg_exe_manipulating_windows_services_registry_keys.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_privilege_escalation.yml,3 T1547.001,Yes,https://github.com/splunk/security-content/blob/develop/detections/registry_keys_used_for_persistence.yml,3 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/kubernetes_azure_scan_fingerprint.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_pod_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/gcp_kubernetes_cluster_scan_detection.yml,5 T1526,Yes,https://github.com/splunk/security-content/blob/develop/detections/amazon_eks_kubernetes_pod_scan_detection.yml,5 T1216,No,-,0 T1063,No,-,0 T1036.003,No,-,0 T1569.001,No,-,0 T1118,No,-,0 T1571,No,-,0 T1069.002,No,-,0 T1089,No,-,0 T1143,No,-,0 T1003.006,No,-,0 T1497.002,No,-,0 T1188,No,-,0 T1110,No,-,0 T1531,No,-,0 T1138,No,-,0 T1132,No,-,0 T1546.013,No,-,0 T1026,No,-,0 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_spaces_before_extension.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/execution_of_file_with_multiple_extensions.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_windows_recycle_bin.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/system_processes_run_from_unexpected_locations.yml,5 T1036,Yes,https://github.com/splunk/security-content/blob/develop/detections/suspicious_writes_to_system_volume_information.yml,5 T1102.002,No,-,0 T1033,No,-,0 T1021.006,No,-,0 T1497,No,-,0 T1167,No,-,0 T1136.002,No,-,0 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_api_calls_from_user_roles.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_aws_api_activities_from_unapproved_accounts.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_security_group_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_spike_in_aws_api_activity.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/cloud_compute_instance_created_by_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/detect_new_user_aws_console_login.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user___mltk.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_launched_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_modified_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/abnormally_high_aws_instances_terminated_by_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/ec2_instance_started_with_previously_unseen_user.yml,13 T1078.004,Yes,https://github.com/splunk/security-content/blob/develop/detections/aws_cross_account_activity_from_previously_unseen_account.yml,13